Version 0.2 · Published 15 July 2026
1.1 This Data Processing Agreement (“DPA”) sets out the terms on which Dimply Limited (“Dimply” or the “Processor”) processes personal data on behalf of the customer (the “Customer” or the “Controller”) in connection with the Dimply platform and related services (the “Services”).
1.2 This DPA forms part of, and is subject to, the agreement between the parties for the provision of the Services (the “Agreement”) — whether an order form, a master services agreement, or the Terms of Service accepted by the Customer for a self-service product. Where the Customer accepts the Terms of Service for a self-service product, this DPA is incorporated into and forms part of those Terms of Service.
1.3 This DPA applies only where and to the extent that Dimply processes Customer Personal Data as a processor on the Customer’s behalf. It does not apply to personal data for which Dimply is a controller in its own right, which is addressed in Dimply’s Privacy Policy.
1.4 If there is any conflict between this DPA and the rest of the Agreement in relation to the processing of Customer Personal Data, this DPA prevails.
2.1 Capitalised terms defined in the Agreement have the same meaning in this DPA. In addition:
(a) “Customer Personal Data” means personal data that Dimply processes on behalf of the Customer in providing the Services, as described in Annex 1.
(b) “Data Protection Law” means all laws relating to data protection and privacy that apply to the processing under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and, where applicable, the UK GDPR and the Data Protection Act 2018.
(c) “Sub-processor” means any processor engaged by Dimply to process Customer Personal Data.
(d) “Standard Contractual Clauses” means, as applicable, the clauses approved by the European Commission (Decision (EU) 2021/914) and/or the UK International Data Transfer Addendum.
(e) The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach”, “special category data” and “supervisory authority” have the meanings given in the EU GDPR.
3.1 As between the parties, the Customer is the controller, and Dimply is the processor in respect of Customer Personal Data. Where the Customer is itself, a processor acting for a third-party controller, Dimply acts as a sub-processor, and the Customer’s instructions must be consistent with that controller’s instructions.
3.2 The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of data subjects are set out in Annex 1.
3.3 The Customer is responsible for the accuracy, quality and legality of the Customer Personal Data and for the lawfulness of the instructions it gives.
4.1 The Customer warrants that it has a valid lawful basis for the processing of Customer Personal Data and, where special category data is processed, a condition under Article 9 of the EU GDPR.
4.2 The Customer is responsible for providing all required privacy information and notices to data subjects, and for obtaining any consents required, in relation to the processing carried out through the Services.
4.3 The Customer configures the Services — including any profiling, scoring, decision logic and retention settings — and is responsible for the lawfulness and effects of that configuration, including any obligations under Article 22 of the EU GDPR (automated decision-making). Dimply acts in accordance with the Customer’s configuration and documented instructions.
4.4 The Customer’s instructions to Dimply must comply with Data Protection Law.
5.1 Processing of documented instructions.
(a) Dimply will process Customer Personal Data only on the Customer’s documented instructions — including those set out in this DPA and the Agreement, and as given through the Customer’s configuration and use of the Services — unless required to do otherwise by law, in which case Dimply will, where legally permitted, inform the Customer first.
(b) Dimply will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law (without any obligation to provide legal advice).
5.2 Confidentiality. Dimply will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
5.3 Security. Dimply will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to Article 32 of the EU GDPR. Dimply’s current measures are described in Annex 2. Dimply maintains certification to ISO/IEC 27001:2022.
5.4 Sub-processors.
(a) The Customer gives Dimply general written authorisation to engage Sub-processors to process Customer Personal Data, subject to this clause. Dimply’s current Sub-processors are listed in Annex 3.
(b) Dimply will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA and will remain liable to the Customer for its Sub-processors’ acts and omissions.
(c) Dimply will give the Customer at least 30 days’ prior notice of the addition or replacement of a Sub-processor. The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and, if unresolved, the Customer may terminate the affected Services.
5.5 Data subject rights.
(a) Taking into account the nature of the processing, Dimply will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Data Protection Law.
(b) If Dimply receives a request directly from a data subject relating to Customer Personal Data, it will not respond substantively (other than, where appropriate, to acknowledge receipt or as required by law). It will promptly notify the Customer and forward the request. Responsibility for responding rests with the Customer as controller.
5.6 Assistance. Taking into account the nature of the processing and the information available to it, Dimply will provide reasonable assistance to the Customer with data protection impact assessments, prior consultation with a supervisory authority, and the Customer’s obligations to keep Customer Personal Data secure and to notify of personal data breaches.
5.7 Personal data breach.
(a) Dimply will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
(b) The notification will describe, to the extent known, the nature of the breach, its likely consequences, and the measures taken or proposed. Where the information is not all available at once, it may be provided in phases without undue delay.
(c) Dimply will reasonably assist the Customer in meeting the Customer’s own obligations to notify supervisory authorities and data subjects. Responsibility for those notifications rests with the Customer as controller.
5.8 International transfers.
(a) Dimply hosts and processes Customer Personal Data within the European Economic Area.
(b) Where Dimply or a Sub-processor transfers Customer Personal Data outside the EEA or the UK, Dimply will ensure an appropriate transfer mechanism is in place — such as the Standard Contractual Clauses (with the UK Addendum where relevant), an adequacy decision, or the EU–US / UK Data Privacy Framework — together with any additional safeguards required. Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference, and Dimply acts as data importer.
5.9 Deletion or return. On termination or expiry of the Services, and at the Customer’s choice, Dimply will delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Deletion carried out through the Services (for example, where an end-user deletes their account) extends to associated data derived for that individual.
5.10 Records and audit.
(a) Dimply will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the EU GDPR.
(b) Dimply will allow for and contribute to audits. To minimise disruption, Dimply may satisfy an audit request by providing its ISO/IEC 27001 certification and related reports; where these are insufficient, the Customer (or an auditor it mandates, bound by confidentiality) may audit no more than once in any 12 months, and following a personal data breach affecting its data, on reasonable notice and during business hours.
6.1 The Services include AI-enabled features, which the Customer configures and for which the Customer remains the controller. The AI-enabled processing is described in Annex 4.
6.2 Dimply does not use Customer Personal Data to train or improve any AI model. The third-party AI models used in the Services are accessed through a private instance within Dimply’s own cloud environment, and Customer Personal Data sent to those models is not used by the model providers to train or improve their models.
6.3 Where the Customer configures profiling or scoring (for example, a financial health score), the logic and its use are determined by the Customer, which remains responsible for compliance, including any obligations under Article 22 of the EU GDPR.
6.4 Any special category data that a data subject volunteers within a conversational feature is used only within that interaction and does not persist into a profile or is referenced in later interactions, except as the Customer configures.
7.1 Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
8.1 This DPA takes effect when the Customer accepts the Agreement or the applicable Terms of Service and continues for as long as Dimply processes Customer Personal Data. Provisions that by their nature should survive termination (including clauses 5.9 and 5.10) will do so.
9.1 This DPA is governed by the law that governs the Agreement and, in the absence of a choice of law, by the laws of Ireland.
9.2 Except as set out in this DPA, the Agreement remains in full force. In the event of a conflict regarding the processing of Customer Personal Data, this DPA prevails, followed by the Standard Contractual Clauses where applicable.
For enterprise customers, this DPA is executed as part of the Agreement. For self-service products, acceptance is electronic under the Terms of Service, and no signature is required.
| Controller | The Customer |
|---|---|
| Processor | Dimply Limited |
| Subject matter | Provision of the Dimply platform and Services to the Customer |
| Duration | For the term of the Agreement, and until deletion or return of Customer Personal Data under clause 5.9 |
| Nature and purpose | Hosting, parsing, transforming, routing and presenting Customer Personal Data to deliver the digital financial experiences the Customer configures, including the AI-enabled features described in Annex 4 |
| Types of personal data | As determined by the Customer’s configuration, it may include identity and contact data, account identifiers, financial, product and policy data, transaction data, behavioural and interaction data, and free-text conversational inputs. |
| Special category data | Not required by the Services; may be processed only where the Customer configures it, or where a data subject volunteers it within a conversational feature (used within that interaction only — see clause 6.4) |
| Categories of data subjects | The Customer’s end-users (for example, its customers or scheme members) and other individuals whose personal data the Customer includes in the Services |
The specific data types and categories are determined by each Customer’s configuration of the Services.
Dimply maintains the following measures, which may be updated to reflect technical developments provided the overall level of security is not reduced:
Dimply’s current Sub-processor is:
| Sub-processor | Location | Service | Data processed |
|---|---|---|---|
| Google Cloud EMEA Limited | Ireland (processing in the EEA — Belgium and Frankfurt) | Cloud hosting and infrastructure, and access to third-party AI models via Google Vertex AI (private instance) | Customer Personal Data processed through the Services |
The third-party AI model provider is engaged through Google Vertex AI as part of that service. Dimply maintains the current list of Sub-processors and makes it available to the Customer on request; changes are notified under clause 5.4.
The Services include the following AI-enabled features. In each case, the Customer configures the feature and remains the controller; Dimply processes Customer Personal Data on the Customer’s instructions.
A customer-facing assistant that the Customer configures to help its end-users understand their financial position, drawing on the Customer’s own data, calculations and journeys. End-users can send free-text messages, which are stored in the platform. Conversation logs are retained in accordance with the Customer’s configuration and are deleted when an end-user deletes their account. Holi draws on verified information the Customer has made available, through controlled requests to the platform’s data layer, rather than querying underlying databases directly.
AI components operate on the current end-user’s context to deliver the configured experience — for example, a decision component that makes real-time branching decisions within a journey, and a processing component that derives or fetches a data point for use later in the experience — within the boundaries the Customer has configured.
The platform can generate profiles, insights, or scores for an individual end user (for example, a financial health score) using logic configured by the Customer. The platform does not generate these automatically; what is produced and how it is used are determined by the Customer.
The platform is designed so that AI surfaces and personalises information rather than providing regulated financial advice or recommending financial products, and is supported by configured guardrails and automated testing to detect and correct drift. Experiences generated with the build tools are reviewed and published by a person before going live. Customer Personal Data is not used to train or improve any AI model.